logo

Ostap malware analysis (Backswap dropper)

ID: dced8a03-c630-58b1-87b6-ccca79a8d982

STIX ID: report--dced8a03-c630-58b1-87b6-ccca79a8d982

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2018-06-01

Date Updated: 2026-04-19

Author: Paweł Srokosz

...
...

Executive summary: This report analyzes the Ostap JSE/JScript dropper campaigns (notably active in Poland) that deliver banking malware families and have evolved from simple downloaders into persistent distribution botnets. Key findings include delivery via ACE archives disguised with a .rar extension, large obfuscated JSE payloads, POST-based C2 sending system and process info, configurable execution headers (e.g. you_god_damn_right), persistence via Startup and self-update, sandbox/analysis detection, and destructive propagation to removable media; the report also lists characteristic URL/parameter patterns and sample notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.